Remote Code Execution Vulnerability in node-opcua by Node-OPCUA
CVE-2026-69200
3.7LOW
What is CVE-2026-69200?
A vulnerability exists in node-opcua, an OPC UA implementation for TypeScript and Node.js, prior to version 2.145.0. This flaw is found in the fieldsToJson method, where unsanitized field names can lead to unintended manipulation of Object.prototype via an attacker-controlled proto.pollutedKey path. Exploiting this vulnerability may result in denial of service or corruption of application logic, particularly in environments where event fields are exposed to the fieldsToJson method.
Affected Version(s)
node-opcua < 2.145.0
